IP Library › Granted Patent US 11,711,242
Granted Patent B2
US 11,711,242 · App. 17/234,504 · Granted Jul 25, 2023

Secure SD-WAN port information distribution

Inventor: Linda Dunbar (Plano, TX)
Assignee: Huawei Technologies Co., Ltd.
H04L12/4675H04L12/4633H04L45/02H04L45/64H04L63/0428H04L69/326H04L63/0209
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,711,242
App. No.
17/234,504
Granted
Jul 25, 2023
Kind
B2
Abstract

A Software Defined Wide Area Network (SD-WAN) edge node is disclosed. The SD-WAN edge node includes edge node SD-WAN ports coupled to untrusted underlay networks. The SD-WAN edge node transmits a first Border Gateway Protocol (BGP) update message advertising WAN (Wide Area Network) properties of the edge node SD-WAN ports to a local controller via an encrypted channel over the untrusted underlay network. The SD-WAN edge node receives a second BGP update message from the local controller, the second BGP update message advertising WAN properties of peer node SD-WAN ports of a peer node. The SD-WAN edge node establishes a security association with the peer node over the untrusted underlay networks based on the WAN properties of the edge node SD-WAN ports and the WAN properties of the peer node SD-WAN ports.

Claims (39)

1. A Software Defined Wide Area Network (SD-WAN) edge node comprising:

one or more edge node SD-WAN ports configured to couple to one or more untrusted underlay networks and one or more trusted underlay networks;

a transmitter;

a receiver;

a non-transitory memory comprising computer executable instructions; and

a processor coupled to the transmitter, the receiver, and the memory, wherein the computer executable instructions, when executed by the processor, cause the SD-WAN edge node to:

transmit a first Border Gateway Protocol (BGP) update message advertising wide area network (WAN) properties of the edge node SD-WAN ports to a local controller via an encrypted channel over the untrusted underlay networks;

receive a second BGP update message from the local controller, the second BGP update message advertising WAN properties of peer node SD-WAN ports of a peer node;

and

establish a security association with the peer node or the peer node SD-WAN ports of the peer node over the untrusted underlay networks based on the WAN properties of the edge node SD-WAN ports and the WAN properties of the peer node SD-WAN ports.

2. The SD-WAN edge node of claim 1 , wherein the WAN properties of the edge node SD-WAN ports describes SD-WAN port capabilities and tunnel end-point attributes, and wherein the WAN properties of the edge node SD-WAN ports are encoded in a Network Layer Reachability Information (NLRI) field of the first BGP update message.

3. The SD-WAN edge node of claim 1 , wherein the WAN properties of the edge node SD-WAN ports comprises a tunnel end point, a private port address, a port internet protocol security (IPsec) capability, a SD-WAN routing policy, tunnel encryption data, or combinations thereof.

4. The SD-WAN edge node of claim 1 , wherein the WAN properties of the edge node SD-WAN ports is included in an overlay Subsequent Address Family Identifier (SAFI) specific overlay networks.

5. The SD-WAN edge node of claim 4 , wherein the overlay SAFI contains a NLRI length, a SD-WAN type, a port distinguisher, a SD-WAN site identifier (ID), and a SD-WAN node ID.

6. The SD-WAN edge node of claim 1 , wherein the WAN properties of the edge node SD-WAN ports are included in a SD-WAN tunnel encapsulation attribute.

7. The SD-WAN edge node of claim 6 , wherein the SD-WAN tunnel encapsulation attribute includes a tunnel type, an internet protocol security (IPsec) security association (SA) attribute, and an encapsulation extension type length value (TLV).

8. A local controller comprising:

a transceiver;

a non-transitory memory comprising computer executable instructions;

a processor coupled to the transceiver and the non-transitory memory, wherein the computer executable instructions, when executed by the processor cause the local controller to:

receive a first Border Gateway Protocol (BGP) update message advertising first wide area network (WAN) properties of first peer node Software Defined Wide Area Network (SD-WAN) ports of a first peer node via a first encrypted channel over one or more untrusted underlay networks, the first BGP update message received via the transceiver;

receive a second BGP update message advertising second wide area network (WAN) properties of second peer node SD-WAN ports of a second peer node via a second encrypted channel over the untrusted underlay networks, the second BGP update message received via the transceiver;

forward the first BGP update message to the second peer node via the transceiver; and

forward the second BGP update message to the first peer node via the transceiver to support establishment of a security association between the first peer node SD-WAN ports and the second peer node SD-WAN ports based on the first WAN properties and the second WAN properties.

9. The local controller of claim 8 , wherein the first WAN properties describes SD-WAN port capabilities and tunnel end-point attributes of the first peer node SD-WAN ports, and wherein the WAN properties of the first peer node SD-WAN ports are encoded in a Network Layer Reachability Information (NLRI) field of the first BGP update message.

10. The local controller of claim 8 , wherein the first WAN properties comprises a tunnel end point, a private port address, a port internet protocol security (IPsec) capability, a SD-WAN routing policy, tunnel encryption data, or combinations thereof.

11. The local controller of claim 8 , wherein the first WAN properties are included in an overlay Subsequent Address Family Identifier (SAFI) specific to overlay networks.

12. The local controller of claim 11 , wherein the overlay SAFI contains a NLRI length, a SD-WAN type, a port distinguisher, a SD-WAN site identifier (ID), and a SD-WAN node ID.

13. The local controller of claim 8 , wherein the first WAN properties are included in a SD-WAN tunnel encapsulation attribute.

14. The local controller of claim 13 , wherein the SD-WAN tunnel encapsulation attribute includes a tunnel type, an internet protocol security (IPsec) security association (SA) attribute, and an encapsulation extension type length value (TLV).

15. A method implemented in a Software Defined Wide Area Network (SD-WAN) edge node, the method comprising:

advertising, by the SD-WAN edge node, SD-WAN port properties via a secure channel with a Border Gateway Protocol (BGP) route reflector, wherein SD-WAN ports are connected to private networks and public untrusted networks, and wherein the SD-WAN port properties are advertised via a BGP update message Network Layer Reachability Information (NLRI) field;

receiving, by the SD-WAN edge node, SD-WAN port properties of a peer node from the BGP route reflector based on peer group policies; and

establishing, by the SD-WAN edge node, a secure pairwise channel with the peer node based on the SD-WAN port properties of the SD-WAN edge node and the SD-WAN port properties of the peer node.

16. The method of claim 15 , wherein the NLRI field is included in a SD-WAN subsequent address family identifier (SAFI) for advertising properties of SD-WAN ports that face untrusted networks.

17. The method of claim 16 , wherein the SD-WAN SAFI includes a NLRI length field indicating a length of the NLRI, a SD-WAN type field defining an encoding of the NLRI field, a port distinguisher including a SD-WAN edge node port identifier (ID), a SD-WAN site ID identifying a common property shared by a set of SD-WAN edge nodes, and a SD-WAN node ID identifying the SD-WAN edge node.

18. The method of claim 17 , wherein the port distinguisher uniquely identifies a corresponding SD-WAN port, and wherein the port distinguisher includes an internet protocol (IP) address of the corresponding SD-WAN port, network address translation (NAT) information for a private IP address, and IP security (IPsec) security association related information for the corresponding SD-WAN port.

19. The method of claim 17 , wherein the common property indicated in the SD-WAN site ID is used to steer an overlay route to traverse specific geographic regions for policy reasons.

20. The method of claim 15 , wherein the NLRI is described by a tunnel encapsulation attribute including a tunnel type indicating a SD-WAN port property, a network address translation (NAT) sub-type length value (TLV) describing information regarding SD-WAN tunnel end points, an IP security (IPsec) security association (SA) attribute sub-TLV including information for establishing IPsec SAs with the peer node, and a port sub-TLV including additional properties of a corresponding SD-WAN port.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2023
From: FUTUREWEI TECHNOLOGIES, INC.
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 063835/0725 →
Continuity (3)
Continuation PCTUS2019056960 · Oct 18, 2019
Provisional Application 62748146 · Oct 19, 2018
Related Publication 20210243053A1 · Aug 5, 2021